TREZOR-SHIPMONK BREACH — 13,689 CUSTOMERS. NOT THE SEEDS. THE ORDER RECORDS.
"One of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal." — Trezor.
The Max read. This is not a seed compromise. Trezor's wallets, firmware, and cryptographic layer are fine. The breach is at ShipMonk — Trezor's third-party fulfillment partner — and it hit the customer records that pass through the shipping stack. 11,742 customers with full PII exposed: name, email, phone, shipping address. Another 1,947 with partial exposure: name, city, email. Total: 13,689 operators now on a list they did not consent to.
Why this class of breach is worse than it looks. The ColdCard entropy failure two weeks ago compromised seed material for a specific firmware cohort. That was cryptographic. This is operational. Names, phone numbers, and shipping addresses tell an attacker who owns a hardware wallet and where they physically live. That is the input to the $5-wrench attack, the SIM-swap attack, the coordinated phishing wave, the extortion note. The wallet itself is still secure. The operator behind the wallet just became easier to find.
The seven countries. US, UK, Sweden, Colombia, Brazil, Italy, Portugal. Two of those have well-documented crypto-kidnapping arcs already running (Brazil and Colombia). One has a mature phishing-industrial complex (US). One has a growing sovereignty-operator population that just got its address book scraped (Portugal). The threat model differs by country but the input is the same: fresh operator addresses, 90 days worth, tied to a hardware-wallet purchase.
What Trezor did right. The 90-day data retention window is a real firewall. Everyone who bought a Trezor before May 10 is not in this dataset. That is not luck. That is minimum-necessary-data policy paying off during a supplier breach. The lesson for every operator-facing brand: retain nothing you do not need, and do not trust a third-party fulfillment partner with anything longer than the fulfillment window requires.
The Max compass. The sovereignty stack has two attack surfaces. Cryptographic — where seeds live — and physical — where the operator lives. ColdCard proved the first can fail. Trezor-ShipMonk just proved the second is exposed even when the first holds. Self-custody is a civil liberty. Operational security is the discipline that keeps the liberty usable.
THE BREACH IN THREE LINES
STRUCTURE: ShipMonk, Trezor's third-party fulfillment partner. Not a Trezor system.
SCOPE: 13,689 total — 11,742 full PII, 1,947 partial. Orders within 90 days before Aug 8.
WATCH: Phishing wave over next 30-60 days targeting affected operators. Multisig + off-market fulfillment + fresh burner phone matter more today than yesterday.
SCOPE: 13,689 total — 11,742 full PII, 1,947 partial. Orders within 90 days before Aug 8.
WATCH: Phishing wave over next 30-60 days targeting affected operators. Multisig + off-market fulfillment + fresh burner phone matter more today than yesterday.
The wallets are fine.
The list is not.
The cap is still twenty-one million.
The list is not.
The cap is still twenty-one million.
Decrypt + Trezor disclosure + BitcoinNews · Aug 13, 2026